“Contagious Interview” Targets macOS with FlexibleFerret Malware

2025-02-06 Hive Pro

https://hivepro.com/wp-content/uploads/2025/02/TA2025031.pdf

Attachments

TA2025031.pdf (1 MB)

Thumbnail for “Contagious Interview” Targets macOS with FlexibleFerret Malware

This attack exploits job seekers and developers, tricking them into installing malware disguised as legitimate applications. These tactics align with previously documented North Korean cyber-espionage campaigns. Beyond targeting job seekers, attackers have expanded their reach to GitHub developers, creating fake issues on repositories to spread FERRET malware droppers. The malware establishes persistence by modifying the User’s Library LaunchAgents folder, masquerading as a legitimate system service.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ccac0f0ba463c414b26ba67b5a3ddaa… 2025-02-06 2025-02-06
HASH 831cdcde47b4edbe27524085a6706fb… 2025-02-03 2025-02-06
HASH 7da429f6d2cdd8a63b3930074797b99… 2025-02-03 2025-02-06
HASH ee7a557347a10f74696dc19512ccc5f… 2025-02-03 2025-02-06
HASH dba1454fbea1dd917712fbece9d6725… 2025-02-03 2025-02-06
HASH de3f83af6897a124d1e85a65818a805… 2025-02-03 2025-02-06
HASH b0caf49884d68f72d2a62aa32d5edf0… 2025-02-03 2025-02-06
HASH bd73a1c03c24a8cdd744d8a513ae8d2… 2025-02-03 2025-02-06
HASH 76e3cb7be778f22d207623ce1907c16… 2025-02-03 2025-02-06
HASH 17e3906f6c4c97b6f5d10e0e0e7f2a2… 2025-02-03 2025-02-06
HASH 8667078a88dae5471f50473a332f6c8… 2025-02-03 2025-02-06
HASH b071fbd9c42ff660e3f240e1921533e… 2025-02-03 2025-02-06
HASH a25dff88aeeaaf9f956446151a9d786… 2025-02-03 2025-02-06
HASH 388ac48764927fa353328104d5a32ad… 2025-02-03 2025-02-06
HASH 203f7cfbf22b30408591e6148f59783… 2025-02-03 2025-02-06
HASH 1a28013e4343fddf13e5c721f91970e… 2025-02-03 2025-02-06
HASH aa172bdccb8c14f53c059c8433c5390… 2025-02-03 2025-02-06
HASH 3e16c6489bac4ac2d76c555eb1c263c… 2025-02-03 2025-02-06
HASH 2e51218985afcaa18eadc5775e6b374… 2025-02-03 2025-02-06
HASH d8245cdf6f51216f29a71f25e70de82… 2025-02-03 2025-02-06
HASH e876ba6e23e09206f358dbd3a3642a7… 2025-02-03 2025-02-06
HASH 828a323b92b24caa5f5e3eff438db45… 2025-02-03 2025-02-06
HASH 7e07765bf8ee2d0b2233039623016d6… 2024-11-07 2025-02-06

Related Actors

Related Reports

« Back